Let me know if this stops it
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint:
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ?type=hppp
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = ?type=hppp
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = web/?type=dspp&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = web/?type=dspp&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ?type=hppp
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = ?type=hppp
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = web/?type=dspp&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = web/?type=dspp&q={searchTerms}
2015-04-16 20:59 - 2015-04-16 20:59 - 00000000 __SHD () C:\Users\Maddie\AppData\Local\EmieBrowserModeList
2015-03-22 01:36 - 2015-03-22 01:36 - 00000000 ____D () C:\ProgramData\cf68e4400000193
2015-03-22 01:22 - 2015-03-22 01:22 - 00000000 ____D () C:\Users\Maddie\Documents\Optimizer Pro
2015-03-22 01:05 - 2015-03-22 01:27 - 00000000 ____D () C:\ProgramData\94d085a862584b48bcb72e5117d0a02d
2015-03-22 01:05 - 2015-03-22 01:05 - 00000000 ____D () C:\ProgramData\d760011c5ff14ebd826285fca2c1323a
2015-03-22 01:02 - 2015-03-22 01:02 - 00000000 __SHD () C:\Users\Maddie\AppData\Local\EmieUserList
2015-03-22 01:02 - 2015-03-22 01:02 - 00000000 __SHD () C:\Users\Maddie\AppData\Local\EmieSiteList
2015-03-22 01:01 - 2015-03-22 01:01 - 00003254 _____ () C:\WINDOWS\System32\Tasks\{55A0C9B4-C496-4730-B291-F76C37A6066D}
2015-03-22 00:44 - 2015-03-22 00:44 - 00000180 _____ () C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-03-09 22:30 - 2015-03-09 22:30 - 0005487 _____ () C:\Users\Maddie\AppData\Roaming\NRMWI
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that